nerdexam
(ISC)2

CSSLP · Question #169

What are the various phases of the Software Assurance Acquisition process according to the U.S. Department of Defense (DoD) and Department of Homeland Security (DHS) Acquisition and Outsourcing…

The correct answer is C. Planning, contracting, monitoring and acceptance, follow-on. According to the DoD and DHS, the Software Assurance Acquisition process comprises four distinct phases: Planning, Contracting, Monitoring and Acceptance, and Follow-on.

Secure Software Supply Chain

Question

What are the various phases of the Software Assurance Acquisition process according to the U.S. Department of Defense (DoD) and Department of Homeland Security (DHS) Acquisition and Outsourcing Working Group?

Options

  • AImplementing, contracting, auditing, monitoring
  • BRequirements, planning, monitoring, auditing
  • CPlanning, contracting, monitoring and acceptance, follow-on
  • DDesigning, implementing, contracting, monitoring

How the community answered

(30 responses)
  • A
    3% (1)
  • C
    93% (28)
  • D
    3% (1)

Why each option

According to the DoD and DHS, the Software Assurance Acquisition process comprises four distinct phases: Planning, Contracting, Monitoring and Acceptance, and Follow-on.

AImplementing, contracting, auditing, monitoring

While implementing and monitoring are parts of the broader software lifecycle, 'auditing' is an activity that occurs across phases, and this choice does not align with the specific four-phase model.

BRequirements, planning, monitoring, auditing

'Requirements' is typically part of the planning phase, and 'auditing' is an activity, not a standalone phase in this specific model.

CPlanning, contracting, monitoring and acceptance, follow-onCorrect

The Software Assurance Acquisition process, as outlined by the DoD and DHS, typically includes a Planning phase to define needs, a Contracting phase for procurement, a Monitoring and Acceptance phase for oversight and validation, and a Follow-on phase for post-deployment assurance. These distinct phases ensure software assurance throughout the acquisition lifecycle.

DDesigning, implementing, contracting, monitoring

'Designing' and 'implementing' are development lifecycle phases, not the specific acquisition process phases defined by the DoD/DHS working group for software assurance.

Concept tested: Software Assurance Acquisition Process (DoD/DHS)

Source: https://www.dhs.gov/sites/default/files/publications/Software_Assurance_Pocket_Guide-508.pdf

Topics

#Software Assurance#Acquisition Process#DoD/DHS#Supply Chain Security

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice